File this under things that should not be possible in 2012. The Register reports a Skype password reset flaw that needs nothing more than knowing which email address you signed up with.
The hijack is triggered by signing up for a new Skype account using the email address of another registered user.
That was the attack. Sign up with somebody else’s address, ignore the warning that it is already in use, because Skype lets you carry on anyway, then request a password reset and collect the token in your own client. No access to their inbox required at any point.
It had apparently been doing the rounds on a Russian forum for three months before anybody at Skype noticed, which is the part I find impressive. Password resets are the front door. You would think somebody would be watching it.
via Skype IDs hijackable by ANY FOOL who knows your email address, The Register.